143 skills found · Page 1 of 5
m0nad / DiamorphineLKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
MatheuZSecurity / SingularityStealthy Linux Kernel Rootkit for modern kernels (6x)
mohuihui / AntispyAntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its assistance,you can easily spot and neutralize malwares hidden from normal detectors.
nurupo / RootkitLinux rootkit for Ubuntu 16.04 and 10.04 (Linux Kernels 4.4.0 and 2.6.32), both i386 and amd64
D4stiny / SpectreA Windows kernel-mode rootkit that abuses legitimate communication channels to control a machine.
landhb / HideProcessA basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager
joaoviictorti / ShadowWindows Kernel Rootkit in Rust
XaFF-XaFF / Black Angel RootkitBlack Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.
eversinc33 / BansheeExperimental Windows x64 Kernel Rootkit with anti-rootkit evasion features.
memN0ps / Eagle RsRusty Rootkit - Windows Kernel Rookit in Rust (Codename: Eagle)
Cr4sh / WindowsRegistryRootkitKernel rootkit, that lives inside the Windows registry values data
nbulischeck / TytonKernel-Mode Rootkit Hunter
DualHorizon / BlackpillA Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs
eversinc33 / UnKoverAnti-Rootkit/Anti-Cheat Driver to uncover unbacked or hidden kernel code.
hiteshd / Android RootkitA rootkit for Android. Based on "Android platform based linux kernel rootkit" from Phrack Issue 68
reveng007 / Reveng RtkitLinux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypass infamous rkhunter antirootkit.
SaadAhla / Dark KillA user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Callback Routine registering and ZwTerminateProcess.
alal4465 / Win RootkitA kernel-mode rootkit with remote control
ExaTrack / KdrillPython tool to check rootkits in Windows kernel
XaFF-XaFF / Kernel Process HollowingWindows x64 kernel mode rootkit process hollowing POC.